diff --git a/policy-f18-contrib.patch b/policy-f18-contrib.patch index 4e67e07..a6e4e46 100644 --- a/policy-f18-contrib.patch +++ b/policy-f18-contrib.patch @@ -36033,71 +36033,6 @@ index 83f002c..d09878d 100644 + postgresql_stream_connect(httpd_mojomojo_script_t) + ') ') -diff --git a/mongodb.te b/mongodb.te -new file mode 100644 -index 0000000..7bd7e35 ---- /dev/null -+++ b/mongodb.te -@@ -0,0 +1,59 @@ -+policy_module(mongodb, 1.0.2) -+ -+######################################## -+# -+# Declarations -+# -+ -+type mongod_t; -+type mongod_exec_t; -+init_daemon_domain(mongod_t, mongod_exec_t) -+ -+type mongod_initrc_exec_t; -+init_script_file(mongod_initrc_exec_t) -+ -+type mongod_log_t; -+logging_log_file(mongod_log_t) -+ -+type mongod_var_lib_t; -+files_type(mongod_var_lib_t) -+ -+type mongod_var_run_t; -+files_pid_file(mongod_var_run_t) -+ -+######################################## -+# -+# Local policy -+# -+ -+allow mongod_t self:process signal; -+allow mongod_t self:fifo_file rw_fifo_file_perms; -+ -+manage_dirs_pattern(mongod_t, mongod_log_t, mongod_log_t) -+append_files_pattern(mongod_t, mongod_log_t, mongod_log_t) -+create_files_pattern(mongod_t, mongod_log_t, mongod_log_t) -+setattr_files_pattern(mongod_t, mongod_log_t, mongod_log_t) -+logging_log_filetrans(mongod_t, mongod_log_t, dir) -+ -+manage_dirs_pattern(mongod_t, mongod_var_lib_t, mongod_var_lib_t) -+manage_files_pattern(mongod_t, mongod_var_lib_t, mongod_var_lib_t) -+files_var_lib_filetrans(mongod_t, mongod_var_lib_t, dir) -+ -+manage_dirs_pattern(mongod_t, mongod_var_run_t, mongod_var_run_t) -+manage_files_pattern(mongod_t, mongod_var_run_t, mongod_var_run_t) -+files_pid_filetrans(mongod_t, mongod_var_run_t, dir) -+ -+kernel_read_system_state(mongod_t) -+ -+corenet_all_recvfrom_unlabeled(mongod_t) -+corenet_all_recvfrom_netlabel(mongod_t) -+corenet_tcp_sendrecv_generic_if(mongod_t) -+corenet_tcp_sendrecv_generic_node(mongod_t) -+corenet_tcp_connect_mongod_port(mongod_t) -+corenet_tcp_bind_generic_node(mongod_t) -+ -+dev_read_sysfs(mongod_t) -+dev_read_urand(mongod_t) -+ -+fs_getattr_all_fs(mongod_t) -+ diff --git a/mono.te b/mono.te index dff0f12..ecab36d 100644 --- a/mono.te